CVE-2024-29510
medium · 6.3Artifex Ghostscript before 10.03.1 allows memory corruption, and SAFER sandbox bypass, via format string injection with a uniprint device.
6.3
CVSS
28.0%
EPSS (exploit prob.)
98th
EPSS percentile
2024-07-03
Published
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N
Weaknesses
CWE-693
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| artifex | ghostscript | < 10.03.1 |
Check a specific version with /api/v1/cve/match.
References
- https://bugs.ghostscript.com/show_bug.cgi?id=707662
- https://codeanlabs.com/blog/research/cve-2024-29510-ghostscript-format-string-exploitation/
- https://www.openwall.com/lists/oss-security/2024/07/03/7
- https://bugs.ghostscript.com/show_bug.cgi?id=707662
- https://codeanlabs.com/blog/research/cve-2024-29510-ghostscript-format-string-exploitation/
- https://www.openwall.com/lists/oss-security/2024/07/03/7
- https://www.vicarius.io/vsociety/posts/critical-vulnerability-in-ghostscript-cve-2024-29510
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2024-29510